[go: up one dir, main page]

ATE460803T1 - Verfahren und system zur abschwächung verteilter dienstverweigerungsangriffe auf grundlage einer schätzung der dichte der ip-nachbarschaft - Google Patents

Verfahren und system zur abschwächung verteilter dienstverweigerungsangriffe auf grundlage einer schätzung der dichte der ip-nachbarschaft

Info

Publication number
ATE460803T1
ATE460803T1 AT08154393T AT08154393T ATE460803T1 AT E460803 T1 ATE460803 T1 AT E460803T1 AT 08154393 T AT08154393 T AT 08154393T AT 08154393 T AT08154393 T AT 08154393T AT E460803 T1 ATE460803 T1 AT E460803T1
Authority
AT
Austria
Prior art keywords
histogram
sender
source
computer system
smoothed
Prior art date
Application number
AT08154393T
Other languages
English (en)
Inventor
Mehran Roshandel
Markus Goldstein
Matthias Reif
Armin Stahl
Thomas Breue
Original Assignee
Deutsche Telekom Ag
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Deutsche Telekom Ag filed Critical Deutsche Telekom Ag
Application granted granted Critical
Publication of ATE460803T1 publication Critical patent/ATE460803T1/de

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0236Filtering by address, protocol, port number or service, e.g. IP-address or URL
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1458Denial of Service
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/141Denial of service attacks against endpoints in a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)
  • Multi Processors (AREA)
AT08154393T 2008-04-11 2008-04-11 Verfahren und system zur abschwächung verteilter dienstverweigerungsangriffe auf grundlage einer schätzung der dichte der ip-nachbarschaft ATE460803T1 (de)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
EP08154393A EP2109282B1 (de) 2008-04-11 2008-04-11 Verfahren und System zur Abschwächung verteilter Dienstverweigerungsangriffe auf Grundlage einer Schätzung der Dichte der IP-Nachbarschaft

Publications (1)

Publication Number Publication Date
ATE460803T1 true ATE460803T1 (de) 2010-03-15

Family

ID=39671864

Family Applications (1)

Application Number Title Priority Date Filing Date
AT08154393T ATE460803T1 (de) 2008-04-11 2008-04-11 Verfahren und system zur abschwächung verteilter dienstverweigerungsangriffe auf grundlage einer schätzung der dichte der ip-nachbarschaft

Country Status (4)

Country Link
EP (1) EP2109282B1 (de)
AT (1) ATE460803T1 (de)
DE (1) DE602008000799D1 (de)
ES (1) ES2341144T3 (de)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102045331B (zh) * 2009-10-22 2014-01-22 成都市华为赛门铁克科技有限公司 查询请求报文处理方法、装置及系统
EP2619958B1 (de) 2010-09-24 2018-02-21 Verisign, Inc. Ip-priorisierungs- und reihungsverfahren und system zur erkennung und unterdrückung von ddos
US9392576B2 (en) 2010-12-29 2016-07-12 Motorola Solutions, Inc. Methods for tranporting a plurality of media streams over a shared MBMS bearer in a 3GPP compliant communication system
US8151341B1 (en) 2011-05-23 2012-04-03 Kaspersky Lab Zao System and method for reducing false positives during detection of network attacks
US10075467B2 (en) * 2014-11-26 2018-09-11 Verisign, Inc. Systems, devices, and methods for improved network security
CN109981656B (zh) * 2019-03-29 2021-03-19 成都知道创宇信息技术有限公司 一种基于cdn节点日志的cc防护方法
CN110474878B (zh) * 2019-07-17 2021-09-24 海南大学 基于动态阈值的DDoS攻击态势预警方法和服务器

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050249214A1 (en) * 2004-05-07 2005-11-10 Tao Peng System and process for managing network traffic
KR101111099B1 (ko) * 2004-09-09 2012-02-17 아바야 테크놀러지 코퍼레이션 네트워크 트래픽 보안 방법들 및 시스템들

Also Published As

Publication number Publication date
ES2341144T3 (es) 2010-06-15
EP2109282A1 (de) 2009-10-14
EP2109282B1 (de) 2010-03-10
DE602008000799D1 (de) 2010-04-22

Similar Documents

Publication Publication Date Title
ATE460803T1 (de) Verfahren und system zur abschwächung verteilter dienstverweigerungsangriffe auf grundlage einer schätzung der dichte der ip-nachbarschaft
WO2008091785A3 (en) System and method for determining data entropy to identify malware
DE602006001357D1 (de) Sicheres Verfahren zur Benachrichtigung einer Dienstbeendigung
TWI584148B (zh) Methods and devices for identifying user risks
CN107517195B (zh) 一种内容分发网络定位攻击域名的方法和装置
HK1245465A1 (zh) 對從通信和內容中提取的承諾和要求的管理
RU2017101889A (ru) Система и способ обнаружения вредоносных программ с алгоритмом генерации доменных имен и систем, зараженных такими вредоносными программами
WO2008063790A3 (en) Method and apparatus for efficient spectrum management in a communications network
DE602004021043D1 (de) Verfahren und system zur erkennung von attacken in drahtlosen datenkommunikationsnetzen
WO2005114464A3 (en) System and method for providing remediation management
WO2007084973A3 (en) Network security system and method
DE502004008199D1 (de) Verfahren zur Zuordnung einer IP-Adresse zu einem Gerät
TW201640405A (zh) 網站攻擊防禦方法及裝置
NZ583300A (en) System for authentication of server and communications and protection against phishing
WO2011115991A3 (en) Methods, systems, and computer readable media for communicating policy information between a policy charging and rules function and a service node
DE602006021224D1 (de) Verfahren zum schutz eines netzwerkdienstkontos, system und vorrichtung hierzu
WO2012138586A3 (en) Mobile expense capture and reporting
CN108259473B (zh) Web服务器扫描防护方法
CN105447385B (zh) 一种多层次检测的应用型数据库蜜罐实现系统及方法
CN101056199A (zh) 一种点对多点接入网的上行突发性能监控方法
ATE445275T1 (de) Verfahren, system und vorrichtung zur verkehrsverwaltung in einem mpls-netzwerk
ATE484913T1 (de) System, verfahren und vorrichtung zur bereitstellung sekundärer informationen für eine kommunikationsvorrichtung
US20160294860A1 (en) Honey user
WO2005119945A3 (en) Optical line termination, optical access network, and method and apparatus for determining network termination type
ATE493817T1 (de) Verfahren zum austausch von suchvorgängen zwischen einer informatikanwendung eines mobilen endgeräts und einem instant-messaging-server

Legal Events

Date Code Title Description
RER Ceased as to paragraph 5 lit. 3 law introducing patent treaties